Method and apparatus for preventing network attack
Abstract
A method for preventing a network attack, including: receiving, by a first network node in a Ethernet virtual private network (EVPN), a first packet, where the first packet carries a first media access control (MAC) address, and the first MAC address is a source MAC address of the first packet; and determining first MAC entry information, where the first MAC entry information includes a correspondence between the first MAC address, an identifier of the first MAC address, and egress port information of the first MAC address, and the identifier of the first MAC address is used to indicate that an egress port corresponding to the first MAC address is a trusted port. This method can reduce a risk that the EVPN breaks down caused by attacking the EVPN by an attacker.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for preventing a network attack, wherein the method is used in an Ethernet virtual private network (EVPN), the EVPN comprises a plurality of network nodes, and the method is performed by a first network node in the plurality of network nodes and comprises:
receiving a first packet, wherein the first packet carries a first media access control (MAC) address, and the first MAC address is a source MAC address of the first packet; and determining first MAC entry information, wherein the first MAC entry information comprises a correspondence between the first MAC address, an identifier of the first MAC address, and egress port information of the first MAC address, and the identifier of the first MAC address is used to indicate that the first MAC address is trusted.
2 . The method according to claim 1 , wherein the first packet is received from a first port of the first network node, and the determining of the first MAC entry information comprises:
determining that the first port is configured as a trusted port; and determining the first MAC entry information based on the first MAC address and the egress port information of the first MAC address, wherein the egress port information of the first MAC address indicates the first port.
3 . The method according to claim 2 , wherein the determining of the first MAC entry information based on the first MAC address and the egress port information of the first MAC address comprises:
determining that pre-stored second MAC entry information does not comprise the first MAC address, or comprises the first MAC address but does not comprise the egress port information of the first MAC address; updating the second MAC entry information; and determining updated second MAC entry information as the first MAC entry information.
4 . The method according to claim 2 , wherein the determining of the first MAC entry information based on the first MAC address and the egress port information of the first MAC address comprises:
determining that pre-stored second MAC entry information comprises the first MAC address and the egress port information of the first MAC address; and determining the second MAC entry information as the first MAC entry information.
5 . The method according to claim 1 , wherein the first packet is received from a first port of the first network node, and the determining of the first MAC entry information comprises:
determining that the first port is not configured as a trusted port; determining that pre-stored second MAC entry information comprises a MAC address that is the same as the first MAC address; determining that an identifier of the MAC address that is the same as the first MAC address indicates that the MAC address is trusted; and determining the second MAC entry information as the first MAC entry information.
6 . The method according to claim 1 , further comprising:
sending a second packet to a network node other than the first network node in the EVPN, wherein the second packet carries the first MAC address and the identifier of the first MAC address.
7 . The method according to claim 6 , wherein an identifier of each MAC address comprised in the second packet is carried in a reserved bit of the second packet.
8 . The method according to claim 2 , wherein the method further comprises:
sending a second packet to a network node other than the first network node in the EVPN, wherein the second packet carries the first MAC address and the identifier of the first MAC address.
9 . The method according to claim 3 , further comprising:
sending a second packet to a network node other than the first network node in the EVPN, wherein the second packet carries the first MAC address and the identifier of the first MAC address.
10 . The method according to claim 4 , further comprising:
sending a second packet to a network node other than the first network node in the EVPN, wherein the second packet carries the first MAC address and the identifier of the first MAC address.
11 . An apparatus for preventing a network attack, wherein the apparatus is configured in an Ethernet virtual private network (EVPN) and comprises:
a memory, configured to store a program code, wherein the memory is connected to at least one processor, and when the program code is executed by the at least one processor, the first device is caused to: receive a first packet, wherein the first packet carries a first media access control (MAC) address, and the first MAC address is a source MAC address of the first packet; and determine first MAC entry information, wherein the first MAC entry information comprises a correspondence between the first MAC address, an identifier of the first MAC address, and egress port information of the first MAC address, and the identifier of the first MAC address is used to indicate that the first MAC address is trusted.
12 . The apparatus according to claim 11 , wherein the first packet is received from a first port of the apparatus, and wherein the first device is further caused to:
determine that the first port is configured as a trusted port; and determine the first MAC entry information based on the first MAC address and the egress port information of the first MAC address, wherein the egress port information of the first MAC address indicates the first port.
13 . The apparatus according to claim 12 , wherein the first device is further caused to:
determine that pre-stored second MAC entry information does not comprise the first MAC address, or comprises the first MAC address but does not comprise the egress port information of the first MAC address; update the second MAC entry information; and determine updated second MAC entry information as the first MAC entry information.
14 . The apparatus according to claim 12 , wherein the first device is further caused to:
determine that pre-stored second MAC entry information comprises the first MAC address and the egress port information of the first MAC address; and determine the second MAC entry information as the first MAC entry information.
15 . The apparatus according to claim 11 , wherein the first packet is received from a first port of the apparatus, and the first device is further caused to:
determine that the first port is not configured as a trusted port; determine that pre-stored second MAC entry information comprises a MAC address that is the same as the first MAC address; determine that an identifier of the MAC address that is the same as the first MAC address indicates that the MAC address is trusted; and determine the second MAC entry information as the first MAC entry information.
16 . The apparatus according to claim 11 , wherein the first device is further caused to:
send a second packet to a network node other than the first network node in the EVPN, wherein the second packet carries the first MAC address and the identifier of the first MAC address.
17 . The apparatus according to claim 16 , wherein an identifier of each MAC address comprised in the second packet is carried in a reserved bit of the second packet.
18 . The apparatus according to claim 12 , wherein the first device is further caused to:
send a second packet to a network node other than the first network node in the EVPN, wherein the second packet carries the first MAC address and the identifier of the first MAC address.
19 . The apparatus according to claim 13 , wherein the first device is further caused to:
send a second packet to a network node other than the first network node in the EVPN, wherein the second packet carries the first MAC address and the identifier of the first MAC address.
20 . The apparatus according to claim 14 , wherein the first device is further caused to:
send a second packet to a network node other than the first network node in the EVPN, wherein the second packet carries the first MAC address and the identifier of the first MAC address.Join the waitlist — get patent alerts
Track US2021297433A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.